detecting-stuxnet-style-attacks - Detect Stuxnet-Style PLC Attacks
Detects attacks that modify PLC logic and spoof sensor readings using logic integrity monitoring and physics-based anomaly detection.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Map the Stuxnet attack chain
- Monitor PLC logic integrity
- Compare PLC blocks with baselines
- Detect physics-based process anomalies
- Cross-validate independent sensor readings
- Generate integrity alerts
Inputs
- Known-good PLC logic baselines
- Current PLC program blocks
- Industrial protocol traffic
- Physics-based process models
- Independent sensor measurements
Outputs
- PLC integrity alerts
- Process anomaly findings
- Monitoring log messages
Requirements
- OT/ICS or SCADA environment
- PLC logic baseline repository
- OT-aware engineering workstation monitoring
- Physics-based process models
- Industrial network monitoring
